CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2024-9865

    Last Modified: 8 Apr 2026

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the transaction log for a booking.

    Published: 24 Oct 2024
    6.1
    Medium

    CVE-2024-9374

    Last Modified: 15 Apr 2026

    The Terms descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 24 Oct 2024
    8.4
    High

    CVE-2024-48542

    Last Modified: 15 Apr 2026

    Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    6.2
    Medium

    CVE-2024-48540

    Last Modified: 15 Apr 2026

    Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    9.8
    Critical

    CVE-2024-48538

    Last Modified: 15 Apr 2026

    Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    9.8
    Critical

    CVE-2024-48514

    Last Modified: 15 Apr 2026

    php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.

    Published: 24 Oct 2024
    8.4
    High

    CVE-2024-48545

    Last Modified: 15 Apr 2026

    Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    7.8
    High

    CVE-2024-45242

    Last Modified: 15 Apr 2026

    EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with the default credentials of admin/admin. An unauthorized attacker in proximity to the Wi-Fi network can exploit this window of time to execute arbitrary OS commands with root-level permissions.

    Published: 24 Oct 2024
    9.8
    Critical

    CVE-2024-41618

    Last Modified: 15 Apr 2026

    Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query.

    Published: 24 Oct 2024
    8
    High

    CVE-2024-45260

    Last Modified: 15 Oct 2025

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.

    Published: 24 Oct 2024
    6.5
    Medium

    CVE-2024-45259

    Last Modified: 15 Oct 2025

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.

    Published: 24 Oct 2024
    9.3
    Critical

    CVE-2024-48548

    Last Modified: 15 Apr 2026

    The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to arbitrarily construct a request to use the app to bind to unknown devices by finding a valid serial number via a bruteforce attack.

    Published: 24 Oct 2024
    8.4
    High

    CVE-2024-48547

    Last Modified: 15 Apr 2026

    Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    8.4
    High

    CVE-2024-48544

    Last Modified: 15 Apr 2026

    Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    8.4
    High

    CVE-2024-48541

    Last Modified: 15 Apr 2026

    Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    9.8
    Critical

    CVE-2024-48539

    Last Modified: 15 Apr 2026

    Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.

    Published: 24 Oct 2024
    8.8
    High

    CVE-2024-48427

    Last Modified: 31 Oct 2024

    A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id

    Published: 24 Oct 2024
    8.8
    High

    CVE-2024-48441

    Last Modified: 15 Apr 2026

    Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

    Published: 24 Oct 2024
    5.5
    Medium

    CVE-2024-48425

    Last Modified: 10 Jun 2025

    A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference.

    Published: 24 Oct 2024
    8
    High

    CVE-2024-45261

    Last Modified: 15 Oct 2025

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.

    Published: 24 Oct 2024
    7.5
    High

    CVE-2024-48142

    Last Modified: 15 Apr 2026

    A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

    Published: 24 Oct 2024
    7.8
    High

    CVE-2024-48423

    Last Modified: 21 Nov 2024

    An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.

    Published: 24 Oct 2024
    6.2
    Medium

    CVE-2024-48426

    Last Modified: 28 May 2025

    A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).

    Published: 24 Oct 2024
    6.5
    Medium

    CVE-2024-48442

    Last Modified: 15 Apr 2026

    Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.

    Published: 24 Oct 2024
    7.2
    High

    CVE-2024-48454

    Last Modified: 23 Apr 2025

    An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

    Published: 24 Oct 2024
    5.3
    Medium

    CVE-2024-40595

    Last Modified: 15 Apr 2026

    An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information.

    Published: 24 Oct 2024
    7.5
    High

    CVE-2024-48139

    Last Modified: 15 Apr 2026

    A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

    Published: 24 Oct 2024
    7.5
    High

    CVE-2024-48140

    Last Modified: 15 Apr 2026

    A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

    Published: 24 Oct 2024
    9.1
    Critical

    CVE-2024-48143

    Last Modified: 15 Apr 2026

    A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders.

    Published: 24 Oct 2024
    9.1
    Critical

    CVE-2024-48145

    Last Modified: 15 Apr 2026

    A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

    Published: 24 Oct 2024
    8.8
    High

    CVE-2024-48440

    Last Modified: 15 Apr 2026

    Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

    Published: 24 Oct 2024
    8.4
    High

    CVE-2024-48546

    Last Modified: 15 Apr 2026

    Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

    Published: 24 Oct 2024
    8.8
    High

    CVE-2024-45263

    Last Modified: 29 Sept 2025

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.

    Published: 24 Oct 2024
    9.8
    Critical

    CVE-2024-41617

    Last Modified: 15 Apr 2026

    Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.

    Published: 24 Oct 2024
    8.8
    High

    CVE-2024-45262

    Last Modified: 15 Oct 2025

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

    Published: 24 Oct 2024
    9.8
    Critical

    CVE-2024-46478

    Last Modified: 24 Jun 2025

    HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.

    Published: 24 Oct 2024
    7.5
    High

    CVE-2024-48141

    Last Modified: 15 Apr 2026

    A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

    Published: 24 Oct 2024
    9.1
    Critical

    CVE-2024-48144

    Last Modified: 15 Apr 2026

    A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

    Published: 24 Oct 2024
    8.6
    High

    CVE-2024-48208

    Last Modified: 4 Sept 2025

    pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.

    Published: 24 Oct 2024
    5.5
    Medium

    CVE-2024-48424

    Last Modified: 10 Jun 2025

    A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.

    Published: 24 Oct 2024
    3.6
    Low

    CVE-2023-50355

    Last Modified: 31 Oct 2024

    HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.

    Published: 23 Oct 2024
    7.5
    High

    CVE-2024-48963

    Last Modified: 30 Oct 2024

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.

    Published: 23 Oct 2024
    7.5
    High

    CVE-2024-48964

    Last Modified: 30 Oct 2024

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.

    Published: 23 Oct 2024
    5.3
    Medium

    CVE-2024-20526

    Last Modified: 31 Oct 2024

    A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device. This vulnerability is due to a logic error when an SSH session is established. An attacker could exploit this vulnerability by sending crafted SSH messages to an affected device. A successful exploit could allow the attacker to exhaust available SSH resources on the affected device so that new SSH connections to the device are denied, resulting in a DoS condition. Existing SSH connections to the device would continue to function normally. The device must be rebooted manually to recover. However, user traffic would not be impacted and could be managed using a remote application such as Cisco Adaptive Security Device Manager (ASDM).

    Published: 23 Oct 2024
    8.6
    High

    CVE-2024-20495

    Last Modified: 11 Aug 2026

    A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation of client key data after the TLS session is established. An attacker could exploit this vulnerability by sending a crafted key value to an affected system over the secure TLS session. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

    Published: 23 Oct 2024
    8.6
    High

    CVE-2024-20494

    Last Modified: 11 Aug 2026

    A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper data validation during the TLS 1.3 handshake. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Note: This vulnerability can also impact the integrity of a device by causing VPN HostScan communication failures or file transfer failures when Cisco ASA Software is upgraded using Cisco Adaptive Security Device Manager (ASDM).

    Published: 23 Oct 2024
    5.3
    Medium

    CVE-2024-20493

    Last Modified: 11 Aug 2026

    A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (DoS) condition. This vulnerability is due to ineffective handling of memory resources during the authentication process. An attacker could exploit this vulnerability by sending crafted packets, which could cause resource exhaustion of the authentication process. A successful exploit could allow the attacker to deny authentication for Remote Access SSL VPN users for several minutes, resulting in a temporary DoS condition.

    Published: 23 Oct 2024
    6
    Medium

    CVE-2024-20485

    Last Modified: 11 Aug 2026

    A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a specific file when it is read from system flash memory. An attacker could exploit this vulnerability by restoring a crafted backup file to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.

    Published: 23 Oct 2024
    6.5
    Medium

    CVE-2024-20482

    Last Modified: 1 Nov 2024

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker must have a valid account on the device that is configured with a custom read-only role. This vulnerability is due to insufficient validation of role permissions in part of the web-based management interface. An attacker could exploit this vulnerability by performing a write operation on the affected part of the web-based management interface. A successful exploit could allow the attacker to modify certain parts of the configuration.

    Published: 23 Oct 2024
    5.8
    Medium

    CVE-2024-20481

    Last Modified: 11 Aug 2026

    A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials.

    Published: 23 Oct 2024